Security Engineer (Hybrid)

B5 Recruiting

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

B5 Recruiting is partnering with a client to hire an experienced Security Engineer to advance the Microsoft security ecosystem across endpoints, cloud, identities, email, and business apps. You will configure Defender XDR, Purview, and Defender for Endpoint, while aligning governance and compliance with FedRAMP-related controls.

This role requires strong collaboration with SOC, governance, and audit teams. The ideal candidate will implement and mature security controls, tune policies, and

Qualifications

  • Hands-on experience with Microsoft Defender XDR and the Microsoft security ecosystem.
  • Experience implementing or administering Microsoft Defender for Endpoint, including ASR policies.
  • Practical knowledge of Purview and Data Loss Prevention controls.
  • Experience with Defender for Cloud and Azure security/compliance controls.
  • Familiarity with Microsoft Sentinel, SIEM integrations, security monitoring, and incident response.

Responsibilities

  • Configure and expand Purview DLP controls across endpoints, M365, email, and cloud apps.
  • Review policy coverage and identify gaps that could create compliance or data protection risks.
  • Partner with governance and compliance stakeholders to translate requirements into practical DLP controls.
  • Support policy tuning, monitoring, and audit preparation.
  • Configure Defender for Endpoint and ASR rules, tune endpoint policies, and reduce unnecessary alerts.
  • Link endpoint telemetry with Microsoft Sentinel for improved investigations.
  • Support the modernization of Azure security monitoring and Defender for Cloud across IaaS and PaaS.
  • Maintain cloud security policies aligned with security standards and regulatory frameworks, including FedRAMP-related controls.
  • Use Azure governance tools like Azure Policy and Secure Score to improve security posture.
  • Design and maintain integrated Microsoft security environments across Defender XDR components and Sentinel.

Skills

Microsoft Defender XDR
Defender for Endpoint
Purview & DLP
Azure security & governance
Microsoft Sentinel
Cloud security controls

Tools

Microsoft Defender for Endpoint
Azure Policy
Secure Score
Microsoft Purview
M365 security stack

Job description

Overview

B5 Recruiting is partnering with a client seeking an experienced Security Engineer to support the implementation and maturation of its Microsoft security ecosystem. This position will play a key role in strengthening enterprise security controls across endpoints, cloud infrastructure, identities, email, and business applications. The engineer will be responsible for configuring and integrating Microsoft security technologies, improving compliance visibility, and helping transition newly implemented controls into day-to-day security operations. The ideal candidate brings strong hands-on experience with Microsoft Defender XDR, Microsoft Purview, Defender for Endpoint, Defender for Cloud, Azure security, and Microsoft Sentinel, along with the ability to work cross-functionally with security operations, governance, compliance, and audit teams.

Key Responsibilities:
Microsoft Purview & Data Protection:
  • Configure and expand Microsoft Purview Data Loss Prevention controls across endpoints, Microsoft 365 environments, email, and supported cloud applications.
  • Review policy coverage and identify potential gaps that could create compliance or data protection risks.
  • Partner with governance and compliance stakeholders to translate organizational requirements into practical DLP controls.
  • Support ongoing policy tuning, monitoring, and audit preparation.
Endpoint Security & Threat Prevention:
  • Configure and implement Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules.
  • Evaluate security controls against prioritized threat scenarios and established cybersecurity frameworks.
  • Tune endpoint policies to balance security effectiveness with business operations and minimize unnecessary alerts or disruptions.
  • Connect endpoint telemetry and alerts with Microsoft Sentinel to improve investigation and incident-response workflows.
Azure & Cloud Security:
  • Support the modernization of Azure security and compliance monitoring using telemetry-driven controls and reporting.
  • Configure Microsoft Defender for Cloud across IaaS and PaaS environments.
  • Maintain cloud security policies aligned with organizational security standards and applicable regulatory frameworks, including FedRAMP-related controls.
  • Use Azure governance capabilities such as Azure Policy, Secure Score, and automated remediation to improve security posture and reduce manual intervention.
Microsoft Defender XDR Integration:
  • Help design and maintain an integrated Microsoft security environment across technologies such as:
    • Microsoft Defender for Endpoint.
    • Microsoft Defender for Identity.
    • Microsoft Defender for Office 365.
    • Microsoft Defender for Cloud Apps.
    • Microsoft Defender for Servers.
    • Microsoft Sentinel.
  • Improve visibility and correlation of security events across endpoint, identity, cloud, and collaboration environments.
  • Support the use and configuration of Microsoft Copilot for Security to improve SOC investigation and response workflows.
  • Assist with testing, troubleshooting, and optimization of integrations across the Microsoft security stack.
Operational Readiness & Knowledge Transfer:
  • Develop documentation, procedures, and operational playbooks for newly implemented security capabilities.
  • Partner with SOC and cybersecurity teams to transition solutions from implementation into steady-state operations.
  • Provide knowledge transfer and training to security personnel on new controls, features, dashboards, and investigation workflows.
  • Support audit, compliance, and security teams with evidence collection and control validation when required.
What We’re Looking For:
  • U.S. Citizenship required.
  • Must reside within reasonable commuting distance of Washington, DC.
  • Strong hands-on experience with Microsoft Defender XDR and the Microsoft security ecosystem.
  • Experience implementing or administering Microsoft Defender for Endpoint, including ASR policies.
  • Practical knowledge of Microsoft Purview and Data Loss Prevention controls.
  • Experience with Microsoft Defender for Cloud and Azure security/compliance controls.
  • Familiarity with Microsoft Sentinel, SIEM integrations, security monitoring, and incident response.
  • Understanding of Azure governance and security technologies such as Azure Policy and Secure Score.
  • Experience working in environments with formal security, regulatory, or audit requirements.
  • Ability to document technical processes and collaborate with SOC, cybersecurity, compliance, governance, and audit stakeholders.

Experience with FedRAMP, FERC-related security requirements, Microsoft Copilot for Security, or large enterprise Microsoft security deployments would be highly valuable.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer – Microsoft Security
Security Engineer – Microsoft Security

B5 Recruiting • Washington

On-site
USD 140,000 - 180,000
Security Engineer, Data
Security Engineer, Data

Applied Systems • Indiana (PA)

On-site
USD 120,000 - 170,000
Security Engineer – Microsoft Defender XDR & Cloud
Security Engineer – Microsoft Defender XDR & Cloud

B5 Recruiting • Washington

On-site
USD 140,000 - 180,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

LevelBlue • United States

On-site
USD 120,000 - 160,000
Defender XDR Security Engineer - Microsoft Cloud
Defender XDR Security Engineer - Microsoft Cloud

B5 Recruiting • Washington

On-site
USD 120,000 - 180,000
Security solution Architect
Security solution Architect

Digital Minds Global Technologies Inc. • Bellevue (KY)

Remote
USD 171,924,000 - 220,416,000
Lead Microsoft Security Engineer
Lead Microsoft Security Engineer

Capitol Careers LLC • Washington

Hybrid
USD 150,000 - 200,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000